---
title: "Attacker Drains 200 ETH From Dormant MakerDAO Auction Keeper"
description: "A legacy keeper contract lost $542,982 in ETH-A collateral after an unauthenticated function let an attacker settle and claim unsettled 2020 auction lots."
url: https://basisdesk.news/news/makerdao-legacy-auction-keeper-exploited-200-eth
published: 2026-10-07T18:46:20.222Z
modified: 2026-10-07T18:46:20.222Z
section: Security & Hacks
author: Basis Desk Newsroom (AI-generated, source-verified)
sentiment: bearish
tickers: [ETH, MKR]
tags: [MakerDAO, CertiK, Ethereum, Exploits, DeFi]
license: Quote with attribution to Basis Desk (basisdesk.news). Not financial advice.
---

# Attacker Drains 200 ETH From Dormant MakerDAO Auction Keeper

A legacy keeper contract lost $542,982 in ETH-A collateral after an unauthenticated function let an attacker settle and claim unsettled 2020 auction lots.

## At a glance

- **What happened:** An attacker exploited an unauthenticated function in a legacy MakerDAO auction-keeper contract to drain 200 ETH on Oct. 6.
- **Why it matters:** The incident reveals that unsettled assets from historical liquidations in unmaintained proxy contracts remain vulnerable to extraction.
- **Who is affected:** The private owner and operator of the legacy auction-keeper contract.
- **What's next:** No next step announced.
- **Primary source:** [MakerDAO Legacy Auction Keeper Incident Analysis](https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis) — certik.com

## Key points

- An attacker drained 200 ETH ($542,982) from a legacy MakerDAO auction-keeper contract on Oct. 6 [1].
- The keeper possessed unsettled lots won with zero bids during MakerDAO's March 2020 Black Thursday crash [1].
- Missing access control allowed the attacker to gain full delegation over the keeper's Vat balance and route proceeds to Tornado Cash [1].

## Editorial remark

- **Context:** MakerDAO suffered severe auction liquidations during the March 2020 market crash, leaving multiple zero-bid auctions uncollected onchain in keeper contracts for years.
- **Impact:** The loss is isolated to the private operator of the legacy auction-keeper contract, with no direct loss to MakerDAO's active protocol reserves.
- **Watch:** Monitoring onchain addresses linked to Tornado Cash deposits to track potential further laundering of the remaining stolen ether.

An attacker drained 200 $ETH ($542,982 at the time of the incident) from an unmaintained MakerDAO auction-keeper contract on Ethereum mainnet on Oct. 6, according to an analysis by blockchain security firm CertiK [1]. The stolen assets stemmed from four 50 ETH lots won with zero bids during MakerDAO's "Black Thursday" liquidations in March 2020 that were left unsettled [1].

CertiK reported that the breach exploited an access control omission in keeper implementation `0x68399ed8aa33C5b43F863EE6782de492006A5546` [1]. While other sensitive functions required authorization checks, an unauthenticated method allowed any caller to register an arbitrary adapter module [1]. Upon invocation, the keeper executed `Vat.hope()`, giving the malicious module complete authority over the keeper's internal balance in MakerDAO's core accounting contract before invoking an execution callback [1].

## Unsettled Collateral and Fund Movement

Inside the callback, the attacker's module initiated settlement on the retired ETH-A Flipper contract for auctions 1457 through 1460 [1]. Because any entity can settle finalized auctions, the contract credited 200 ETH of ETH-A collateral to the keeper's internal balance, which the attacker immediately transferred away using the freshly granted delegation [1]. The attacker then exited the position through the ETH-A GemJoin contract and forwarded the funds as wrapped ether [1].

Blockchain records show the operation was funded through an initial 0.1 ETH withdrawal from Tornado Cash minutes before the attack [1]. Six minutes after the exploit transaction confirmed, the perpetrator began laundering the stolen capital through the privacy mixer in 10 ETH increments [1]. MakerDAO governance systems were not directly modified during the incident, as the vulnerability resided entirely within a third-party legacy keeper proxy rather than MakerDAO's active core contracts [1]. At the time of writing, MakerDAO's governance token $MKR traded at $1,844, down 7.9% over the past 24 hours.

## Sources

1. [MakerDAO Legacy Auction Keeper Incident Analysis](https://www.certik.com/blog/makerdao-legacy-auction-keeper-incident-analysis) — certik.com, 2026-10-07

---
Basis Desk Newsroom · AI-generated, source-verified · https://basisdesk.news/about/how-we-use-ai
